> ## Documentation Index
> Fetch the complete documentation index at: https://docs.visitoai.com/llms.txt
> Use this file to discover all available pages before exploring further.

# API and connector permissions

> Choose domain access for M2M API keys and MCP connections in Codex or Claude.

Visito uses the same domain selector for API keys and the Visito authorization screen for MCP connections. A business is the tenant boundary: a credential or connection can access only its selected business.

MCP is available by default for all enabled businesses. An active registered admin must approve each connection and its permissions.

## Choose access by domain

New selections start with **No access**. Choose **Read** or **Read & write** for each domain you need. **Read all** selects available read actions; **Read & write all** selects every available action, including writes; **Clear all** removes the selection. At least one permission is required to create a key or connect an app.

| Domain | Read | Read & write adds |
| - | - | - |
| Channels | Connected channels | Read only |
| Properties | Properties and locations | Read only |
| Conversations | Conversations, messages, delivery status, available operators | Send replies and start conversations; manage assignments, reviews, handoffs, status and AI pauses |
| WhatsApp templates | Templates | Create templates and send approved templates |
| CRM & follow-ups | Contacts, opportunities, drafts, follow-ups and automation settings | Update opportunities, manage and send follow-ups, change automatic follow-up settings |
| Reservations | Reservations and guest messaging activity | Change automatic guest messages and senders |
| Knowledge | Sources and usage | Add, update and delete sources |
| Commerce | Catalog and sales | Create, update and delete catalog items |
| Custom tools | Definitions and activity logs | Create, update, delete and execute tools |
| Reporting | Messaging reports | Read only |
| Webhooks | Webhooks and delivery activity | Create, change and delete webhooks, including delivery destinations |

**Read & write includes consequential actions within the domain**, including sending, deletion, automation or execution where listed. It grants permission; selecting it does not itself perform those actions. Provider readiness, business rules and other server checks still apply.

## Narrow an integration's access

Expand **Customize permissions** to select individual actions. Partial selections display **Custom**. Existing API keys and connections keep their exact permissions and show grouped summaries; expand a domain to inspect the granted actions. Seeing Custom does not mean access has changed.

MCP consent can grant only the scopes requested by the registered OAuth client. A **Limited request** shows the exact available actions for that domain. Read & write includes only those requested actions, even if the client requested writes without reads. MCP excludes webhooks and operational handoff creation; those remain M2M-only.

Examples:

* Reporting integration: Reporting → Read; all other domains → No access.
* Catalog editor: Commerce → Read & write, or use Customize permissions for catalog-only access without sales reads.
* Conversation assistant: Conversations → Read for review, or Read & write when sending and conversation management are intended.

## Compatibility and connection approval

Domain choices expand to existing scope strings. The public API still accepts and returns the same `scopes` arrays; no wildcard permissions or new authorization format were introduced. Existing keys and OAuth grants do not gain new scopes when the catalog grows.

Codex and Claude control their own tool-approval interfaces. Their approval prompts do not replace Visito's tenant and scope checks. Switching businesses in the Visito dashboard does not switch a saved connection.

Custom installation is the v1 distribution method. Store/directory publication is deferred to v2. See [Claude setup](/api-docs/claude-connector) for the verified custom connection flow.
